Austria - Information Access Law (BGBl. I Nr. 5/2024)

Freedom of Information Act

Informationsfreiheitsgesetz

Austria

RAI-AT-NA-INFFRIN-2024
Effective: September 1, 2025
In Force(In Force)
ActTransparency and DisclosureAccountability and DocumentationData Protection and Privacy
Export PDF

The Informationsfreiheitsgesetz (IFG) establishes a constitutionally backed right of access to information held by public authorities in Austria and creates a two‑pillar transparency regime: proactive publication of information of general interest via an information register and a right to request information. The Act was promulgated in BGBl. I Nr. 5/2024 (26 February 2024) and entered into force predominantly on 1 September 2025.

Overview

The Informationsfreiheitsgesetz (IFG) was promulgated as BGBl. I Nr. 5/2024 and implements a constitutionally anchored right of access to official information alongside a duty for public bodies to proactively publish information of general interest. The law creates a twin structure: (1) proactive publication obligations (via an information register) and (2) a request/response mechanism enabling individuals and legal persons to obtain information from administrations, courts and certain public or publicly‑controlled entities. Most provisions of the IFG entered into force on 1 September 2025 and the law is aimed at shifting the default from secrecy to openness while preserving narrowly defined confidentiality exemptions.

Definitions

Key legal definitions under the IFG include "information" (any record kept for official or enterprise purposes in the sphere of a public organ, foundation, fund, institution or publicly‑controlled enterprise), "information of general interest" (materials that concern or are relevant to a general audience such as organisational data, plans, statistics, studies, reports and contracts), and "information‑obliged organs" (organs of the federal, state and municipal administrations, courts, institutions under public control and private persons/organisations insofar as they perform public administrative tasks). The statute draws specific distinctions for third‑party data and personal data, and it links secrecy exceptions to proportionality tests balancing public interest in disclosure against protected interests (see § 6 IFG and implementing guidance).

Governance and Institutional Framework

The IFG establishes a multi‑actor implementation framework. The Federal Chancellery published official explanatory material and coordinates administrative implementation; the central metadata publication channel is the national portal at data.gv.at. The Austrian Data Protection Authority (DSB) has a statutory advisory and evaluative role (§ 15 IFG): it must publish guidelines, support training for information‑obliged bodies and evaluate the Act’s application. Judicial oversight is provided by the administrative courts (Verwaltungsgerichte); the IFG prescribes shortened procedural timelines for appeal cases. Criminal‑law safeguards were amended in parallel (revision of § 310 StGB) to preserve penalties for unlawful disclosure where a statutory secrecy obligation remains in force; this balancing was legislatively coordinated with the IFG introduction.

Key Focus Areas

The IFG focuses on (a) proactive transparency through publishing information of general interest in machine‑readable, accessible formats via the information register; (b) an enforceable, general right of access to information on request with clear procedural steps and time limits; (c) a structured exemption regime protecting public order, security, privacy and legitimate business secrets subject to proportionality; (d) tailored rules for private entities performing public tasks; and (e) data protection coordination to ensure disclosures respect personal data rights. The proactive pillar requires public bodies to identify, catalogue and publish metadata about their information holdings. Requests may be filed in any technically feasible form and authorities must provide access without undue delay (normally within four weeks, with a possible four‑week extension). Remedies and redress are available through formal Bescheide and expedited administrative court review if access is denied.

Implementation Framework

Implementation relies on operational and technical measures: (1) creation and maintenance of the information register (metadata with links to published resources) hosted via data.gv.at; (2) internal administrative processes to receive, triage and respond to IFG requests (including routes for urgent or complex requests and third‑party involvement procedures); (3) guidance and training delivered by the DSB on handling personal data and redactions; (4) publication standards to ensure machine readability, multilingualism and web accessibility in line with the Web Accessibility Act; (5) documentation and reporting obligations for evaluation purposes. Smaller municipalities (under 5,000 inhabitants) are exempted from proactive publication but must still accept and respond to requests. The Act relieves applicants from fees for the exercise of access rights; only minor direct costs (e.g., copies or physical media) may be charged in limited circumstances.

Monitoring and Evaluation

Monitoring is built into the statute: the Data Protection Authority must evaluate application of the IFG and report publicly on its activities. Informationspflichtige Stellen are required to keep records and to report metadata and compliance data via central channels (including reporting obligations to Justiz‑Online for evaluation purposes). The DSB’s published IFG guidance and FAQs accompany the rollout and will be periodically updated based on observed practice and court jurisprudence. Civil society actors, academic projects and independent monitoring initiatives (e.g., transparency NGOs and academic platforms) have also been active in testing and reporting on practical compliance.

Penalties, Liability, and Appeals

The IFG itself does not create a comprehensive administrative sanction regime for failure to publish or to respond; instead, enforcement primarily relies on judicial remedies (requests for a formal Bescheid and expedited administrative court review). On the criminal side, the Criminal Code was amended to replace the old “Amtsverschwiegenheit” offence with a revised § 310 StGB (“violation of a duty to maintain secrecy”) that retains criminal liability (up to three years’ imprisonment) where a public official unlawfully discloses information that must remain secret. Commentators and civil society noted the absence of direct administrative fines in the IFG and flagged implementation and enforcement gaps, urging strengthened administrative follow‑through and oversight mechanisms.

Relationship to Other Instruments

The IFG operates alongside and interacts with multiple legal instruments: the Federal Constitution (B‑VG) was amended to include the new constitutional right (Art. 22a B‑VfG) that underpins the IFG; the General Data Protection Regulation (GDPR) and Austrian data‑protection law continue to apply and are explicitly referenced in the IFG with the DSB’s advisory role; sector‑specific access regimes (e.g., financial secrecy, judicial confidentiality rules, police law, national security statutes) take precedence where they contain special access rules; and the Web Accessibility Act and open‑data standards govern format and accessibility requirements for published materials.

International Alignment

The IFG brings Austria into closer alignment with Council of Europe and EU expectations on transparency and open government, and with international best practice on proactive publication and access‑on‑request. The law’s two‑pillar approach mirrors trends across EU Member States and OECD recommendations, while its interplay with data‑protection safeguards responds to GDPR obligations. Observers have compared the Austrian model to other national FOI regimes and noted differences in enforcement mechanisms (particularly the limited direct sanctioning powers), calling for continued alignment of procedural safeguards and implementation practices with European standards.

Implementation Timeline

EventDate
Promulgation (BGBl. I Nr. 5/2024)2024-02-26
Main provisions enter into force2025-09-01
DSB publishes initial IFG guidance and FAQs2025-06-30
First operational use / civil‑society test requests (public reporting)2025-09-01
Amendment to Criminal Code (§ 310 StGB) effective2025-09-01

Compliance Checklist

RequirementAction for public bodies
Proactive publication of information of general interestIdentify datasets/docs; publish metadata via data.gv.at; ensure machine‑readable formats and accessibility
Request handlingDesignate IFG contact points; accept requests in any technical form; log receipt dates
Response timelinesRespond without undue delay; ordinarily within 4 weeks; document any extension (max +4 weeks)
Redaction & third‑party involvementApply proportionality; consult third parties where required; provide partially redacted releases
Data protection coordinationFollow DSB guidance and document privacy assessments for disclosures
Recordkeeping & reportingMaintain logs and submit required metadata for DSB evaluation and audits

Sources and References

SourceType
BGBl. I Nr. 5/2024 - Amendment of B‑VfG and InformationsfreiheitsgesetzPrimary Source
RIS consolidated text: Informationsfreiheitsgesetz §1 (scope)Primary Source
RIS consolidated text: Informationsfreiheitsgesetz §8 (response time)Primary Source
Austrian Data Protection Authority – IFG guidance and FAQsPrimary Source
Federal Chancellery – Information on the new InformationsfreiheitsgesetzPrimary Source
Plain English

Austria's new Freedom of Information Act (Informationsfreiheitsgesetz, or IFG) creates a constitutional right for everyone to access information held by public authorities, aiming to shift the default from secrecy to openness. This law applies broadly to federal, state, and municipal administrations, courts, public institutions, and even private entities performing public administrative tasks within Austria.

Starting September 1, 2025, public bodies face two primary obligations. First, they must proactively publish "information of general interest" – such as organisational data, plans, statistics, studies, reports, and contracts – in machine-readable formats on the national data.gv.at portal. Second, they must respond to information requests from individuals and legal entities. Authorities typically have four weeks to respond, with a possible four-week extension if needed. While the law promotes transparency, it includes specific exemptions to protect public order, security, privacy, and legitimate business secrets, requiring a careful balancing act. The Austrian Data Protection Authority (DSB) will provide guidance on how to handle personal data when disclosing information.

A key aspect to note is the law's enforcement. The IFG itself does not impose direct administrative fines on public bodies for failing to publish or respond to requests. Instead, enforcement primarily relies on individuals pursuing formal decisions and expedited reviews through administrative courts. This means citizens must actively challenge non-compliance. In a related development, the Criminal Code was updated to maintain penalties, including up to three years' imprisonment, for public officials who unlawfully disclose information that *must* remain secret, balancing the new transparency with existing confidentiality duties. Smaller municipalities (under 5,000 inhabitants) are exempt from the proactive publication requirement but must still accept and respond to information requests.

Plain-English rewrite by Regulations.ai — not legal advice. Verify against the official text.

© Regulations.AI — created on 13-Jun-2026